-
Bug
-
Resolution: Fixed
-
Low
-
2.0.1
-
None
-
None
-
Tested with JIRA 4.0
Maximum Unchanged Password Days (Internal Directory) configuration is not respected by the Applications, only by the Crowd console.
If the password is expired, Crowd still allow users to authenticate to the Applications.
This is not a minor bug, it is at least a critical bug. You allow users to log in with a password that is not valid any more! When our security-officer gets info about this he will request to shut down Crowd and replace it by an other software.
When the JIRA-Stack is not able to handle "maximum unchanged days" crowd should not tell JIRA that the incredenials are valid.
Fix this immediate please!